download-exodus[.]io
“Exodus Wallet: Download the world's leading bitcoin and crypto wallet”
download-exodus.io — Belum terverifikasi. Peniruan identitas merek: Exodus; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLScan malicious verdict; Google Safe Browsing flagged; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); CF Radar malicious; PhishDestroy score 100/100. Registrar: Hosting Concepts.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, download-exodus.io, is a confirmed phishing infrastructure designed to impersonate the Exodus cryptocurrency wallet. Analysis indicates the site presents itself as the official Exodus download portal, using the page title 'Exodus Wallet: Download the world's leading bitcoin and crypto wallet' to deceive users into downloading malicious software or disclosing sensitive credentials. The threat specifically targets cryptocurrency holders by mimicking legitimate wallet distribution channels, potentially leading to unauthorized access to digital assets or installation of malware designed to exfiltrate private keys and recovery phrases. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on November 5, 2025, through Hosting Concepts B.V. d/b/a Registrar.eu, and resolves to the IP address 45.82.82.240 located in Russia (AS9123 JSC TIMEWEB). Security vendors have flagged the domain in 21 out of 95 VirusTotal scans, while it appears on four distinct security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. Google Safe Browsing has also classified the domain as phishing, and no valid SSL certificate was detected, further reducing its legitimacy. The combination of these technical indicators confirms the domain's role in active brand impersonation campaigns. Users who visited download-exodus.io should immediately cease all interaction with the site and any downloaded files. If credentials or recovery phrases were entered, affected wallets should be considered compromised, and funds should be transferred to a new, secure wallet using a clean device. Devices used to access the domain should undergo a full malware scan using updated security tools. Additionally, users should monitor their cryptocurrency transactions for unauthorized activity and enable multi-factor authentication on all related accounts. Given the domain's current offline status, no further direct threat is posed, but vigilance is advised for similar impersonation attempts.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive